AccessData Certified Examiner (ACE) — Questions and Answers
Question 1: What is 'slack space' in digital forensics?
- Space reserved for the MFT expansion zone
- The unused area between the logical end of a file and the physical end of its last allocated cluster (Correct answer)
- Unpartitioned space at the end of a disk
- Free space available for new file creation
Correct answer: The unused area between the logical end of a file and the physical end of its last allocated cluster
Slack space is the residual area from where a file's data ends to the physical boundary of the last allocated storage cluster, which can contain remnants of previous data.
Question 2: During a forensic investigation, an examiner discovers that a suspect encrypted files using BitLocker. Which risk mitigation approach should be prioritized to access the data?
- Seek the recovery key from Active Directory or Microsoft account
- Brute-force the BitLocker password immediately
- Reformat the drive to bypass encryption
- Run a live memory acquisition to capture the decryption key (Correct answer)
Correct answer: Run a live memory acquisition to capture the decryption key
Live memory acquisition can capture the BitLocker decryption key if the system is still running, providing the most direct access to encrypted data.
Question 3: Which Windows Security Event ID indicates a successful user account logon?
- Event ID 4625
- Event ID 1102
- Event ID 4688
- Event ID 4624 (Correct answer)
Correct answer: Event ID 4624
Windows Security Event ID 4624 is logged each time a user account successfully authenticates and establishes a logon session.
Question 4: Which AccessData tool is specifically designed for live memory acquisition and analysis of a running system?
- PRTK
- FTK Imager
- MPE+
- FTK (Memory Analysis module) (Correct answer)
Correct answer: FTK (Memory Analysis module)
FTK's memory analysis module, combined with FTK Imager's memory capture capability, supports live RAM acquisition and subsequent analysis within FTK.
Question 5: What is write-blocking and why is it critical during forensic acquisition?
- It encrypts the forensic image during transfer
- It compresses data during imaging to save space
- It speeds up read operations by caching sectors
- It prevents any write commands from reaching the evidence drive, preserving its original state (Correct answer)
Correct answer: It prevents any write commands from reaching the evidence drive, preserving its original state
Write-blockers intercept and discard write commands at the hardware or software level, ensuring no data on the evidence drive is modified during imaging.
Question 6: When FTK identifies an encrypted file during processing, what is the recommended first step before attempting password recovery?
- Mark the file as inaccessible and note it in the report
- Check if the password or key material exists elsewhere in the image (e.g., swap file, registry) (Correct answer)
- Immediately begin a brute force attack
- Export the file and use a third-party tool
Correct answer: Check if the password or key material exists elsewhere in the image (e.g., swap file, registry)
Key material, passwords, or encryption artifacts may exist in other areas of the image such as unallocated space, the registry, or hibernation/swap files, providing a faster path than cracking.
Question 7: An examiner is analyzing Windows Volume Shadow Copies (VSS). What forensic value do they provide?
- They log all network connections made by the system
- They contain encrypted copies of all user passwords
- They provide point-in-time snapshots of the file system allowing recovery of previous file versions (Correct answer)
- They store browser history across all user profiles
Correct answer: They provide point-in-time snapshots of the file system allowing recovery of previous file versions
Volume Shadow Copies are point-in-time snapshots of the file system that can contain previous versions of files, deleted files, and earlier registry states.
Question 8: What is key escrow, and how is it relevant to digital forensic investigations?
- A legal process for compelling suspects to provide their encryption passwords
- A hardware device that stores cryptographic keys securely
- A technique for hiding encryption keys inside other files (steganography)
- A system where encryption keys are held by a trusted third party, potentially allowing lawful access without breaking encryption (Correct answer)
Correct answer: A system where encryption keys are held by a trusted third party, potentially allowing lawful access without breaking encryption
Key escrow allows authorized parties (such as law enforcement with proper legal process) to obtain encryption keys from the holding third party, enabling decryption without cryptanalysis.
Question 9: In which scenario would FERPA (Family Educational Rights and Privacy Act) most directly impact a forensic examiner's ability to access student records during an investigation?
- When recovering deleted files from a faculty member's university laptop
- When analyzing network logs showing unauthorized access from student IPs
- When investigating a university's financial fraud involving federal grants
- When examining a student's academic records without written consent or valid exception (Correct answer)
Correct answer: When examining a student's academic records without written consent or valid exception
FERPA protects the privacy of student education records, requiring written consent or a valid legal exception (such as a court order or subpoena) before disclosure to investigators.
Question 10: What type of password attack attempts every possible combination of characters up to a specified length?
- Dictionary attack
- Rule-based attack
- Rainbow table attack
- Brute force attack (Correct answer)
Correct answer: Brute force attack
A brute force attack systematically tries all possible character combinations, guaranteeing eventual success but requiring significant time and resources.
Question 11: What is the primary purpose of write-blocking hardware in digital forensics?
- To verify the hash of the destination drive
- To speed up the imaging process
- To prevent any data from being written to the original evidence drive (Correct answer)
- To encrypt data on the source drive
Correct answer: To prevent any data from being written to the original evidence drive
Write blockers prevent any modifications to the original evidence drive during the imaging or examination process.
Question 12: What is 'sparse acquisition' in the context of mobile device forensics?
- Acquiring only the SIM card data
- Imaging only non-empty, allocated regions of storage to reduce image size (Correct answer)
- Acquiring data over a slow Bluetooth connection
- Extracting only deleted files using carving
Correct answer: Imaging only non-empty, allocated regions of storage to reduce image size
Sparse acquisition skips empty (zeroed) sectors and records only blocks with actual data, significantly reducing image size for large-capacity devices.
Question 13: According to the order of volatility, which data source must be collected FIRST at a live scene?
- External hard drive image
- Backup tapes in the server room
- Log files stored on disk
- RAM/memory contents (Correct answer)
Correct answer: RAM/memory contents
RAM is the most volatile data source and must be captured before any other action, as it is destroyed immediately when the system loses power.
Question 14: What is the primary goal of digital forensics?
- Prevent all cyber threats
- Erase data from storage devices
- Modify evidence to match legal needs
- Preserve and analyze digital evidence (Correct answer)
Correct answer: Preserve and analyze digital evidence
The primary goal of digital forensics is to systematically identify, preserve, collect, analyze, and present digital evidence in a manner that maintains its integrity and admissibility in legal proceedings. This process aims to uncover facts related to a digital incident or crime without altering the original data. It ensures that findings are reliable and can withstand scrutiny.
Question 15: What distinguishes a logical acquisition from a physical acquisition of a mobile device?
- Physical acquisition works only on iOS devices
- Logical acquisition requires a write-blocker; physical does not
- Logical acquisition captures deleted data; physical does not
- Physical acquisition captures the complete bit-stream; logical captures only accessible files (Correct answer)
Correct answer: Physical acquisition captures the complete bit-stream; logical captures only accessible files
Physical acquisition captures the entire raw storage including deleted and unallocated space, while logical acquisition retrieves only the active file system.
Question 16: What is the purpose of FTK's Known File Filter (KFF)?
- Identify files by known hash values to flag or exclude them, reducing manual review workload (Correct answer)
- Encrypt files marked as sensitive during review
- Create forensic images of entire drives
- Automatically generate a final case report
Correct answer: Identify files by known hash values to flag or exclude them, reducing manual review workload
FTK's KFF uses hash libraries such as NSRL to automatically identify known-good or known-bad files, letting examiners focus on unknown or suspicious items.
Question 17: What does the Windows 'UserAssist' registry key track, and how is its data encoded?
- Recently printed documents, encoded in hexadecimal
- Recently connected USB devices, encoded in Base64
- Active network adapter settings, stored in plain text
- GUI-based program execution history with run counts and timestamps, encoded in ROT13 (Correct answer)
Correct answer: GUI-based program execution history with run counts and timestamps, encoded in ROT13
UserAssist entries, stored ROT13-encoded under HKCU, record the history of programs launched through Windows Explorer including execution counts and last-run timestamps.
Question 18: Under HIPAA, what is the maximum civil penalty per violation category when the covered entity demonstrates willful neglect and fails to correct the violation?
- $1,900,000 (Correct answer)
- $1,000,000
- $50,000
- $10,000
Correct answer: $1,900,000
HIPAA civil penalties for willful neglect not corrected cap at $1,919,173 per violation category per calendar year (adjusted for inflation from the original $1,500,000).
Question 19: What is 'file carving' in digital forensics?
- Securely wiping files from a disk
- Recovering files based on file signatures without relying on file system metadata (Correct answer)
- Hashing all files on a drive for verification
- Encrypting recovered files for secure storage
Correct answer: Recovering files based on file signatures without relying on file system metadata
File carving recovers files by identifying known file headers and footers in raw data when file system metadata is missing or overwritten.
Question 20: Why is timestamping an evidence collection log with UTC rather than local time considered best practice?
- UTC is faster to type than local time zone abbreviations
- UTC eliminates ambiguity from daylight saving time changes and time zone differences across jurisdictions (Correct answer)
- FTK only stores timestamps in UTC format
- Courts do not accept local time zone evidence
Correct answer: UTC eliminates ambiguity from daylight saving time changes and time zone differences across jurisdictions
UTC is a universal reference that avoids the confusion of daylight saving adjustments and cross-jurisdiction time zone discrepancies in multi-location investigations.
Question 21: What is a root cause analysis used for?
- To identify the underlying cause of a problem rather than just addressing symptoms (Correct answer)
- To assign blame to individuals who made mistakes
- To calculate the financial cost of errors
- To document problems for annual reporting
Correct answer: To identify the underlying cause of a problem rather than just addressing symptoms
Root cause analysis is a systematic method used to identify the fundamental underlying cause of a problem, enabling solutions that prevent recurrence rather than just treating symptoms.
Question 22: When preserving ESI under a litigation hold, what is the examiner's primary obligation regarding the organization's automatic email deletion policies?
- Continue auto-deletion unless a court order prohibits it
- Encrypt emails before deletion to demonstrate good faith
- Suspend auto-deletion for potentially relevant data upon notice of litigation (Correct answer)
- Notify opposing counsel before any deletion occurs
Correct answer: Suspend auto-deletion for potentially relevant data upon notice of litigation
Upon reasonable anticipation of litigation, organizations must suspend routine document destruction policies (including auto-deletion) to preserve potentially relevant ESI.
Question 23: A suspect's password-protected ZIP archive uses PKZIP 2.0 (ZipCrypto) encryption. Why is this considered weak from a forensic perspective?
- ZipCrypto is vulnerable to known-plaintext attacks that can recover the key with as little as 12 bytes of known plaintext (Correct answer)
- ZipCrypto uses only 40-bit keys that brute force attacks can break instantly
- ZipCrypto archives can be decompressed without a password using standard tools
- PKZIP 2.0 stores the password hash in the ZIP header in plaintext
Correct answer: ZipCrypto is vulnerable to known-plaintext attacks that can recover the key with as little as 12 bytes of known plaintext
The ZipCrypto algorithm is vulnerable to a known-plaintext attack; if an examiner has an unencrypted copy of even one file in the archive, the encryption key can be recovered rapidly.
Question 24: Which of the following correctly describes the order of volatility from MOST to LEAST volatile?
- CPU registers → RAM → network state → hard disk (Correct answer)
- Network state → optical media → RAM → CPU registers
- Hard disk → RAM → CPU registers → network state
- RAM → hard disk → CPU registers → optical media
Correct answer: CPU registers → RAM → network state → hard disk
CPU registers and cache are the most volatile, followed by RAM, network state, then persistent storage like hard disks and optical media.
Question 25: What forensic value does the Windows hiberfil.sys file provide?
- It contains a compressed snapshot of RAM from the last system hibernation event (Correct answer)
- It stores a backup of the Windows registry hives
- It logs all application crashes and error codes
- It holds browser session cookies from the last active user session
Correct answer: It contains a compressed snapshot of RAM from the last system hibernation event
Hiberfil.sys stores a compressed image of RAM contents saved during hibernation, serving as a partial memory dump available for offline forensic analysis.
Question 26: Which tool is used to recover deleted files in forensic investigations?
- Google Sheets
- Notepad++
- Autopsy (Correct answer)
- Wireshark
Correct answer: Autopsy
Autopsy is a popular open-source digital forensics platform that includes robust capabilities for recovering deleted files. It allows investigators to analyze file systems, identify and carve out deleted data, and reconstruct file fragments. This functionality is crucial for uncovering evidence that suspects may have attempted to conceal by deleting it.
Question 27: A forensic examiner in a state with mandatory data breach notification laws discovers a breach involving Social Security numbers. In most U.S. states, the notification obligation is typically triggered when:
- Unauthorized acquisition of unencrypted personal information is reasonably believed to have occurred (Correct answer)
- The organization's cyber insurance carrier approves the notification
- The breach is confirmed by a third-party auditor
- More than 500 individuals are affected
Correct answer: Unauthorized acquisition of unencrypted personal information is reasonably believed to have occurred
Most state breach notification laws trigger the notification duty when there is reasonable belief that unencrypted personal information was acquired without authorization, regardless of the number of individuals affected.
Question 28: What does 'chain of custody' mean in digital forensic investigations?
- A software dependency chain used by forensic tools
- The sequence of network hops traced during a cyber investigation
- The documented, unbroken chronological record of who handled evidence, when, and under what conditions (Correct answer)
- A linked list of file system clusters allocated to a file
Correct answer: The documented, unbroken chronological record of who handled evidence, when, and under what conditions
Chain of custody documents every person who handled the evidence and all transfers, maintaining its integrity and ensuring its admissibility in legal proceedings.
Question 29: In ACORD Certified Expert, what is the purpose of team-building activities?
- To comply with HR requirements
- To identify the weakest team member
- To waste time during work hours
- To strengthen collaboration, trust, and communication (Correct answer)
Correct answer: To strengthen collaboration, trust, and communication
Team-building activities enhance collaboration, build trust among team members, and improve communication skills.
Question 30: Which of the following best describes 'slack space' in digital forensics?
- Empty sectors at the beginning of a disk
- Space between the end of a file and the end of its last cluster (Correct answer)
- Space reserved for the file system metadata
- Unallocated space at the end of a partition
Correct answer: Space between the end of a file and the end of its last cluster
Slack space is the unused space between the end of a file's data and the end of the last cluster allocated to that file.
Question 31: When examining a BitLocker-encrypted drive, which of the following is the most examiner-friendly recovery method if the recovery key is unavailable?
- Disabling BitLocker through the Windows RE environment
- Imaging the encrypted volume and processing it directly in FTK
- Searching the Microsoft account or Active Directory for the stored BitLocker Recovery Key (Correct answer)
- Running a GPU-accelerated brute force attack against the volume header
Correct answer: Searching the Microsoft account or Active Directory for the stored BitLocker Recovery Key
BitLocker recovery keys are automatically backed up to Microsoft accounts or Active Directory, making this the fastest and most reliable recovery path for examiners.
Question 32: What is a forensic memory dump file used for?
- Backing up NTFS MFT records
- Capturing the contents of RAM at a specific point in time for offline forensic analysis (Correct answer)
- Permanently erasing sensitive files from a drive
- Creating a verified bit-for-bit copy of a hard disk
Correct answer: Capturing the contents of RAM at a specific point in time for offline forensic analysis
A memory dump is a snapshot of RAM contents at the moment of acquisition, enabling offline analysis of volatile artifacts that would otherwise be lost.
Question 33: Which action violates proper chain of custody during evidence handling?
- Allowing an untrained officer to handle the drive without documentation (Correct answer)
- Sealing evidence in a tamper-evident bag
- Photographing the evidence before collection
- Logging each person who accesses the evidence bag
Correct answer: Allowing an untrained officer to handle the drive without documentation
Allowing undocumented access by an untrained person creates a gap in chain of custody and may render the evidence inadmissible.
Question 34: What is the forensic significance of a password found in the Windows Credential Manager or DPAPI-protected storage?
- It only applies to domain accounts and is irrelevant for local account investigations
- It must be decrypted separately using a different DPAPI key before it can be used
- It is stored in an irreversible hash format and cannot be recovered in plaintext
- It may provide the actual password used for encrypted files, websites, or network shares without requiring cracking (Correct answer)
Correct answer: It may provide the actual password used for encrypted files, websites, or network shares without requiring cracking
Windows Credential Manager and DPAPI often store passwords in a form recoverable with the user's account credentials, providing plaintext passwords that can directly unlock encrypted resources.
Question 35: Which standard governs the admissibility of scientific evidence in US federal courts based on peer review and general acceptance?
- Federal Rules 902
- Daubert Standard (Correct answer)
- Locard Standard
- Best Evidence Rule
Correct answer: Daubert Standard
The Daubert Standard, established in Daubert v. Merrell Dow Pharmaceuticals (1993), requires federal courts to evaluate scientific testimony for reliability and relevance.
Question 36: What is the purpose of maintaining a chain of custody in evidence handling?
- Modify evidence to match investigation needs
- Allow anyone to access the evidence freely
- Speed up the forensic process by skipping documentation
- Prevent tampering and maintain documentation (Correct answer)
Correct answer: Prevent tampering and maintain documentation
Maintaining a chain of custody is essential in evidence handling to document every person who has had possession of the evidence, when, and for what purpose. This meticulous record-keeping prevents unauthorized access or tampering, ensuring the evidence's integrity and authenticity. A broken chain of custody can render evidence inadmissible in court, undermining the entire investigation.
Question 37: In FTK, when performing keyword searches across evidence, what advantage does an indexed search provide over a live search?
- Indexed search automatically translates foreign language content
- Live search is always more accurate than indexed search
- Indexed search can find encrypted content
- Indexed search is significantly faster because terms are pre-processed into a searchable index during evidence processing (Correct answer)
Correct answer: Indexed search is significantly faster because terms are pre-processed into a searchable index during evidence processing
FTK builds a full-text index during processing, allowing indexed searches to complete in seconds by querying the pre-built index rather than scanning raw evidence data.
Question 38: What does FTK's 'Known File Filter' (KFF) contribute to a password recovery workflow?
- It excludes known benign files from processing, allowing the examiner to focus on unknown or suspect encrypted files (Correct answer)
- It automatically decrypts files that match known encryption signatures
- It identifies files that have been renamed to hide their extension
- It flags files whose hash matches known malware databases
Correct answer: It excludes known benign files from processing, allowing the examiner to focus on unknown or suspect encrypted files
KFF filters out known-good files (e.g., OS and application files), reducing the dataset so examiners concentrate password recovery efforts on genuinely unknown, potentially relevant encrypted files.
Question 39: What is 'anti-forensics' in the context of digital investigations?
- Techniques used to destroy, conceal, or manipulate digital evidence to impede forensic investigations (Correct answer)
- Encrypting forensic case files to maintain confidentiality
- The process of verifying the integrity of collected evidence
- Writing court-admissible forensic examination reports
Correct answer: Techniques used to destroy, conceal, or manipulate digital evidence to impede forensic investigations
Anti-forensics encompasses methods such as file wiping, timestamp alteration, steganography, and encryption used to obstruct or invalidate forensic analysis.
Question 40: Which of the following tools is commonly used for network forensics analysis?
- Adobe Premiere
- Autopsy
- Wireshark (Correct answer)
- Microsoft Word
Correct answer: Wireshark
Wireshark is a powerful and widely used open-source network protocol analyzer, making it a primary tool for network forensics analysis. It allows investigators to capture and interactively browse network traffic, identify suspicious activities, and reconstruct communication patterns. This capability is essential for understanding network intrusions, data exfiltration, and other network-related incidents.
Question 41: In FTK, when a file is flagged as 'encrypted' after processing, what does this determination typically rely on?
- The file extension matching a known encrypted format list
- File header signatures, entropy analysis, and known encryption format identification (Correct answer)
- The file owner's account being marked as restricted
- The file being located in a system-protected directory
Correct answer: File header signatures, entropy analysis, and known encryption format identification
FTK combines file signature recognition, known encryption format headers, and high-entropy measurements to identify encrypted files, rather than relying solely on extensions.
Question 42: What is the purpose of using a Faraday bag during mobile device acquisition?
- Prevent electrostatic discharge from damaging the device
- Compress file system data for storage
- Keep the device charged during transport
- Block wireless signals to prevent remote wipe commands (Correct answer)
Correct answer: Block wireless signals to prevent remote wipe commands
A Faraday bag blocks cellular, Wi-Fi, and Bluetooth signals, preventing remote wipe or data modification commands from reaching the device.
Question 43: Which file format does FTK Imager use to create a proprietary AccessData forensic image?
- DD (Raw Image)
- E01 (EnCase Evidence File)
- AFF (Advanced Forensic Format)
- AD1 (AccessData Image) (Correct answer)
Correct answer: AD1 (AccessData Image)
AD1 is AccessData's native logical image format, while E01 is EnCase's format; FTK Imager also supports E01 and DD, but AD1 is the AccessData proprietary format.
Question 44: A suspect uses a portable operating system (e.g., Tails OS) booted from USB. How does this affect forensic evidence on the host machine's hard drive?
- The host drive typically contains no artifacts from the session since writes go to RAM or the USB (Correct answer)
- The portable OS installs a hidden partition on the host drive
- Browser history from the portable OS is saved to the host drive's swap file
- The host drive is fully overwritten by the portable OS
Correct answer: The host drive typically contains no artifacts from the session since writes go to RAM or the USB
Privacy-focused live OS distributions like Tails route all writes to RAM, leaving no forensic artifacts on the host hard drive after shutdown.
Question 45: A trainer uses the same program for a sedentary 55-year-old beginner as for a 25-year-old competitive athlete. This approach MOST significantly violates which quality principle?
- ACE continuing education standards
- Emergency response protocols
- Individualization as a core component of quality program design (Correct answer)
- Scope of practice guidelines
Correct answer: Individualization as a core component of quality program design
Individualization is a fundamental quality principle; applying identical programs to clients with vastly different needs compromises safety and effectiveness.
Question 46: Which FTK Imager feature is used to acquire a live memory dump from a running Windows system?
- Add Evidence Item
- Create Disk Image
- Capture Memory (Correct answer)
- Mount Image to Drive Letter
Correct answer: Capture Memory
FTK Imager's 'Capture Memory' option acquires the contents of RAM from a running system and writes it to a .mem or .dmp file for offline analysis.
Question 47: What is 'selective imaging' and when is it appropriate?
- Cloning only the boot partition
- Imaging every other sector to reduce file size
- Imaging only sectors 0-1024 to save time
- Acquiring specific files or folders rather than the entire drive, typically used when a full image is legally or logistically impractical (Correct answer)
Correct answer: Acquiring specific files or folders rather than the entire drive, typically used when a full image is legally or logistically impractical
Selective imaging targets specific data (e.g., documents folder) and is used when a full disk image is impractical, though it sacrifices unallocated space recovery.
Question 48: Why is the Windows pagefile (pagefile.sys) forensically significant?
- It contains the user's complete browsing history
- It stores encrypted copies of the SAM database
- It records a log of all file access operations
- It holds memory pages swapped from RAM to disk, potentially including process data, fragments of documents, and passwords (Correct answer)
Correct answer: It holds memory pages swapped from RAM to disk, potentially including process data, fragments of documents, and passwords
The pagefile contains RAM pages that were swapped to disk, preserving volatile data fragments even after the system is shut down.
Question 49: A forensic lab is assessing the risk of examiner error corrupting digital evidence. Which mitigation technique directly reduces this risk?
- Increasing the number of case files per examiner
- Purchasing additional storage hardware
- Implementing peer review and dual-examiner verification procedures (Correct answer)
- Restricting internet access in the lab
Correct answer: Implementing peer review and dual-examiner verification procedures
Peer review and dual-examiner verification catch errors before they affect evidence integrity, directly reducing the risk of examiner mistakes.
Question 50: What is the primary forensic value of Windows Event Logs?
- They record every keystroke entered by users
- They store a copy of all files created on the system
- They contain the full content of deleted files
- They provide a chronological record of system events including logons, service starts, and security actions (Correct answer)
Correct answer: They provide a chronological record of system events including logons, service starts, and security actions
Windows Event Logs (Security, System, Application) record timestamped system events that enable forensic reconstruction of activity timelines.
Question 51: When acquiring evidence from a live system, which method best preserves volatile memory that would be lost on shutdown?
- Power off immediately and image the drive
- Perform a RAM dump before any disk imaging (Correct answer)
- Create a static disk image only
- Clone the hard drive using a write-blocker
Correct answer: Perform a RAM dump before any disk imaging
RAM dump captures volatile memory contents (running processes, encryption keys, network connections) that are destroyed when power is removed.
Question 52: What is the forensic purpose of analyzing the Windows Recycle Bin artifacts ($I and $R files) on a NTFS volume?
- To identify USB devices previously connected
- To recover the contents of deleted RAM
- To determine the original file path, deletion time, and recover the content of deleted files (Correct answer)
- To view network connection history
Correct answer: To determine the original file path, deletion time, and recover the content of deleted files
$I files store metadata (original path and deletion timestamp) while $R files store the actual deleted file content, together providing complete evidence of deliberate file deletion.
Question 53: What is the function of a write blocker in forensic investigations?
- Remove duplicate data automatically
- Compress evidence for storage
- Prevent modifications to digital evidence (Correct answer)
- Speed up the copying of files
Correct answer: Prevent modifications to digital evidence
The primary function of a write blocker in forensic investigations is to physically or logically prevent any data from being written to the original digital evidence source. This ensures that the integrity of the evidence is maintained during the acquisition and examination process, preventing accidental or intentional alteration. Write blockers are crucial for adhering to the principle of non-alteration of evidence.
Question 54: Under the Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, what must a defense contractor do within 72 hours of discovering a cyber incident affecting covered defense information (CDI)?
- Report the incident to the DoD via the DIBNet portal (Correct answer)
- File a criminal complaint with the FBI Cyber Division
- Notify all subcontractors and halt work until cleared
- Patch all affected systems and submit remediation proof to NIST
Correct answer: Report the incident to the DoD via the DIBNet portal
DFARS 252.204-7012 requires defense contractors to report cyber incidents affecting CDI to the DoD within 72 hours through the DIBNet portal at dibnet.dod.mil.
Question 55: When examining LNK (shortcut) files during a Windows investigation, what type of evidence can they provide?
- A record of deleted user accounts
- Proof of network packet capture
- Encrypted key material for BitLocker volumes
- Evidence of file access including original file path, MAC times, and volume serial number (Correct answer)
Correct answer: Evidence of file access including original file path, MAC times, and volume serial number
LNK files retain metadata about the target file including original path, timestamps, volume serial number, and MAC address, even if the target file is deleted.
Question 56: Which practice best ensures consistency in forensic documentation across multiple examiners within an organization?
- Using different tools for each case
- Each examiner develops their own documentation style
- Adopting standardized report templates and documentation procedures (Correct answer)
- Documenting only the final findings
Correct answer: Adopting standardized report templates and documentation procedures
Standardized templates and procedures ensure that all reports meet the same quality and completeness standards regardless of which examiner authored them.
Question 57: When an ACE examiner needs to validate that a forensic tool produced accurate results, which best practice should be employed?
- Use a validated test image with known artifacts and verify the tool correctly identifies them (Correct answer)
- Compare output with results from the same tool on a different computer
- Accept vendor documentation as sufficient validation
- Run the tool multiple times until consistent results appear
Correct answer: Use a validated test image with known artifacts and verify the tool correctly identifies them
Using a known test image with documented artifacts (such as those from NIST's CFReDS) and verifying the tool correctly identifies them is the accepted scientific method for tool validation.
Question 58: A forensic image hash taken immediately after acquisition differs from the hash taken one week later. What does this indicate?
- The image was stored in a compressed format
- The hashing algorithm changed between calculations
- Normal hash drift due to time-stamping
- The image file has been modified or corrupted since acquisition (Correct answer)
Correct answer: The image file has been modified or corrupted since acquisition
A changed hash value proves the image data is no longer identical to its state at acquisition, indicating tampering or corruption.
Question 59: What is a rule-based (or hybrid) attack in PRTK?
- Combining two dictionary files into a single wordlist
- Using known plaintext to derive the encryption key
- Applying transformation rules (e.g., capitalize, append numbers) to dictionary words to generate candidates (Correct answer)
- Splitting a brute force attack across multiple processors
Correct answer: Applying transformation rules (e.g., capitalize, append numbers) to dictionary words to generate candidates
A rule-based attack applies mutations — such as capitalization, substitution, or appending digits — to dictionary entries to cover predictable password patterns.
Question 60: What does analyzing DNS artifacts during network forensics help an investigator determine?
- The encryption keys used in SSL/TLS sessions
- Which domain names a system resolved, revealing connections to websites, C2 servers, or exfiltration targets (Correct answer)
- The hardware MAC addresses of all devices on a subnet
- The physical location of a network switch
Correct answer: Which domain names a system resolved, revealing connections to websites, C2 servers, or exfiltration targets
DNS resolution records show which domain names a host looked up, helping establish communications with malicious domains, C2 infrastructure, or unauthorized services.
Question 61: What is the purpose of feedback in ACORD Certified Expert professional development?
- To provide constructive guidance for improvement (Correct answer)
- To justify termination
- To criticize mistakes only
- To rank employees
Correct answer: To provide constructive guidance for improvement
Constructive feedback identifies areas of strength and opportunities for improvement, supporting ongoing professional growth.
Question 62: In FTK, what does the 'Explicit Images' filter rely on to categorize photos without manual review?
- PhotoDNA perceptual hashing
- Hash value matching against NSFW databases
- Skin-tone pixel percentage analysis via integrated AI scoring (Correct answer)
- EXIF metadata tags embedded by the camera
Correct answer: Skin-tone pixel percentage analysis via integrated AI scoring
FTK's explicit image detection uses skin-tone pixel analysis combined with AI scoring to flag potentially explicit images for examiner review.
Question 63: In a dictionary attack, what is the primary source material used to attempt password recovery?
- All possible character combinations up to a set length
- Precomputed hash values stored in tables
- Previously known plaintext-ciphertext pairs
- A predefined list of common words and phrases (Correct answer)
Correct answer: A predefined list of common words and phrases
A dictionary attack uses a wordlist of common passwords, words, or phrases as candidates, making it effective against weak or common passwords.
Question 64: In FTK Imager, what format produces a single-file image with integrated hashing, compression, and case metadata?
- E01 (Expert Witness Format) (Correct answer)
- DD (raw)
- ISO 9660
- AFF (Advanced Forensic Format)
Correct answer: E01 (Expert Witness Format)
E01 format embeds MD5/SHA-1 hashes, case metadata, and optional compression within a single segmented or monolithic file.
Question 65: How does FTK analyze web browsing history from a Windows evidence image?
- By reviewing only the browser's LNK shortcut files
- By running keyword searches on the browser executable only
- By examining only the Windows Event Log for browser activity
- By parsing browser artifact databases such as Chrome and Firefox SQLite files and IE index.dat to extract visited URLs and timestamps (Correct answer)
Correct answer: By parsing browser artifact databases such as Chrome and Firefox SQLite files and IE index.dat to extract visited URLs and timestamps
FTK parses browser-specific artifact files (SQLite databases for Chrome/Firefox, index.dat for IE) to reconstruct browsing history with URLs and timestamps.
Question 66: Which FTK search capability enables examiners to locate structured data patterns like SSNs or credit card numbers across all evidence?
- Regular expression (regex) search (Correct answer)
- Evidence image mounting
- Known File Filter (KFF) hash matching
- Bookmark export and review
Correct answer: Regular expression (regex) search
FTK supports regular expression searches, allowing examiners to define patterns such as \d{3}-\d{2}-\d{4} to locate Social Security numbers or similar structured data across all evidence.
Question 67: What does Windows Security Event ID 4625 indicate?
- An audit policy was changed
- A privileged service was started
- A failed logon attempt occurred (Correct answer)
- A user account was created
Correct answer: A failed logon attempt occurred
Event ID 4625 is logged whenever an account fails to authenticate, which is critical for detecting brute force attacks and unauthorized access attempts.
Question 68: Why is hashing important in digital forensics?
- Ensures data integrity with a unique identifier (Correct answer)
- Compresses files for easier storage
- Removes unnecessary data from the investigation
- Encrypts evidence for extra security
Correct answer: Ensures data integrity with a unique identifier
Hashing is crucial in digital forensics because it generates a unique, fixed-size alphanumeric string (hash value) for a given set of data. By comparing the hash value of the original evidence with that of its forensic copy, investigators can verify that no data has been altered or corrupted. This process ensures the integrity and authenticity of the digital evidence throughout the investigation.
Question 69: In FTK, what is the purpose of the 'Detailed Options' hash verification step during evidence processing?
- To compress evidence files before storage
- To compute and record cryptographic hash values (MD5/SHA-1) of evidence items to verify integrity throughout the investigation (Correct answer)
- To index only image files while skipping documents
- To automatically redact sensitive data from the evidence set
Correct answer: To compute and record cryptographic hash values (MD5/SHA-1) of evidence items to verify integrity throughout the investigation
FTK computes MD5 and SHA-1 hashes during evidence processing to create a verifiable integrity baseline, confirming that evidence has not been altered.
Question 70: In FTK, the 'Case Log' feature is primarily used to:
- Generate MD5 reports
- Export bookmarked files
- Record automated actions taken during the case (Correct answer)
- Hash verification of evidence
Correct answer: Record automated actions taken during the case
FTK's Case Log automatically records actions, searches, and events that occur within the case for documentation and audit purposes.
Question 71: What is 'prefetch' analysis used for in a Windows forensic investigation?
- Mapping network shares accessed by the suspect
- Identifying encrypted volumes on a drive
- Recovering deleted emails from PST files
- Determining which applications were executed and when on a Windows system (Correct answer)
Correct answer: Determining which applications were executed and when on a Windows system
Windows Prefetch files (.pf) record application execution data including run count and last run time, proving program execution even after the executable is deleted.
Question 72: What is a rainbow table in the context of password cracking?
- A color-coded matrix for organizing password complexity rules
- A precomputed table of hash values mapped to their plaintext passwords (Correct answer)
- A list of leaked passwords sorted by frequency
- A GUI tool for visualizing password entropy
Correct answer: A precomputed table of hash values mapped to their plaintext passwords
Rainbow tables store precomputed hash-to-plaintext mappings, enabling fast password recovery by looking up a hash rather than computing it in real time.
Question 73: What critical data does RAM (volatile memory) analysis reveal that traditional disk forensics cannot?
- File system allocation maps and MFT records
- Registry hive files stored on disk
- Running processes, active network connections, encryption keys, and decrypted data in memory (Correct answer)
- Files deleted years before the acquisition
Correct answer: Running processes, active network connections, encryption keys, and decrypted data in memory
RAM analysis captures the live system state, including running processes, decrypted content, active connections, and data never written to disk.
Question 74: A suspect's laptop is found with BitLocker encryption enabled and running. What is the FIRST action an examiner should take?
- Boot into a live Linux environment
- Acquire a RAM dump to capture the encryption key (Correct answer)
- Attach a write-blocker and image the disk
- Immediately pull the power cord
Correct answer: Acquire a RAM dump to capture the encryption key
Capturing a RAM dump first recovers the BitLocker key from memory, enabling decryption; powering off would destroy the key.
Question 75: Which type of risk analysis relies on numeric values and statistical data to calculate potential losses?
- Quantitative risk analysis (Correct answer)
- Operational risk analysis
- Qualitative risk analysis
- Subjective risk analysis
Correct answer: Quantitative risk analysis
Quantitative risk analysis uses numerical data—such as asset value, threat frequency, and probability—to produce measurable loss estimates like ALE.
Question 76: What type of traffic does a packet sniffer capture during network forensic analysis?
- Raw network packets traversing the monitored network interface (Correct answer)
- Only wireless beacon and management frames
- Exclusively DNS query and response messages
- Only HTTPS-encrypted web traffic streams
Correct answer: Raw network packets traversing the monitored network interface
A packet sniffer captures all raw packets at the network interface level, providing complete visibility into communications regardless of protocol.
Question 77: What is AccessData's DNA (Distributed Network Attack) feature primarily used for?
- Distributing password cracking workloads across networked computers (Correct answer)
- Decrypting SSL/TLS communications
- Managing distributed forensic case files
- Analyzing network traffic captures
Correct answer: Distributing password cracking workloads across networked computers
DNA leverages multiple networked machines to parallelize and accelerate password recovery operations, dramatically reducing cracking time.
Question 78: Which step must be performed before disconnecting a running server to prevent evidence loss?
- Defragment the file system
- Disable all user accounts on the system
- Document and capture volatile system state including running processes and network connections (Correct answer)
- Run CHKDSK to verify disk integrity
Correct answer: Document and capture volatile system state including running processes and network connections
Before powering down a running server, examiners must document volatile evidence (processes, connections, logged-in users) that will not survive a shutdown.
Question 79: What is a forensic image in digital evidence acquisition?
- A manually edited set of files
- A compressed version of select data
- A summary report of important files
- An exact copy of a digital device (Correct answer)
Correct answer: An exact copy of a digital device
A forensic image is a bit-for-bit, sector-by-sector duplicate of a digital storage device, capturing all data including active files, deleted files, and unallocated space. This exact copy serves as the working evidence for analysis, ensuring the original device remains untouched and its integrity preserved. It is fundamental for maintaining the authenticity and admissibility of digital evidence.
Question 80: An examiner uses FTK to analyze a FAT32 volume and notices directory entries with a first byte of 0xE5. What does this signify?
- A system file protected by Windows File Protection
- A deleted directory entry that may still have recoverable data (Correct answer)
- An extended attribute entry for long file name support
- A volume label entry at the root directory
Correct answer: A deleted directory entry that may still have recoverable data
In FAT file systems, a 0xE5 value in the first byte of a directory entry indicates the file was deleted, though its cluster chain may still hold recoverable data.
Question 81: Which Windows registry location stores previously connected wireless (Wi-Fi) network profiles?
- HKLM\SAM\SAM\Domains\Account\Users
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles and WLAN event logs (Correct answer)
- HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
- HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
Correct answer: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles and WLAN event logs
Windows stores Wi-Fi network history in the NetworkList registry key and WLAN AutoConfig event logs, which can reveal location history based on network associations.
Question 82: Which action best demonstrates the ACE ethical standard of 'professional responsibility'?
- Offering discounts to retain clients showing signs of dropping out
- Maintaining current certification, CPR/AED credentials, and continuing education (Correct answer)
- Sharing successful client case studies without anonymizing details
- Training clients beyond their fitness level to accelerate results
Correct answer: Maintaining current certification, CPR/AED credentials, and continuing education
Professional responsibility includes keeping credentials current and pursuing ongoing education to provide competent service.
Question 83: Which of the following is MOST consistent with continuous quality improvement (CQI) in personal training?
- Maintaining identical session structures regardless of client progress
- Delegating all program adjustments to the facility manager
- Regularly seeking client feedback, reviewing outcomes, and refining practices (Correct answer)
- Using the same programming system for 10 years without updates
Correct answer: Regularly seeking client feedback, reviewing outcomes, and refining practices
CQI is an ongoing cycle of feedback, outcome review, and practice refinement rather than a static approach to service delivery.
Question 84: What does 'timestomping' refer to in a forensic investigation?
- Automatically updating file timestamps during imaging
- Synchronizing system clocks across networked computers
- Deliberately manipulating file timestamps to mislead investigators or establish a false alibi (Correct answer)
- Recording timestamps in the chain of custody log
Correct answer: Deliberately manipulating file timestamps to mislead investigators or establish a false alibi
Timestomping is an anti-forensic technique where an attacker or suspect alters file timestamps to obscure when files were created, modified, or accessed.
Question 85: GPU acceleration in password cracking provides a significant advantage primarily because GPUs:
- Can store more dictionary entries in cache
- Have faster memory access than CPUs
- Operate at higher clock speeds than modern CPUs
- Contain thousands of cores optimized for parallel mathematical operations (Correct answer)
Correct answer: Contain thousands of cores optimized for parallel mathematical operations
GPUs contain thousands of small cores designed for parallel processing, allowing them to compute millions of hash comparisons simultaneously — far exceeding CPU performance for cracking tasks.
Question 86: How often should compliance procedures be reviewed and updated?
- Only when an audit is scheduled
- Every ten years regardless of changes
- Regularly, and whenever regulations change or new risks are identified (Correct answer)
- Once at initial certification and never again
Correct answer: Regularly, and whenever regulations change or new risks are identified
Compliance procedures should be reviewed regularly and updated whenever regulations change, new risks emerge, or organizational changes occur.
Question 87: When examining a RAID-5 array in FTK, which information is CRITICAL for the examiner to obtain before reconstruction?
- The RAID controller firmware version
- The operating system installed on the RAID volume
- Strip size, disk order, and parity rotation scheme (Correct answer)
- The file system type used on the array
Correct answer: Strip size, disk order, and parity rotation scheme
Accurate RAID-5 reconstruction requires knowing the strip size, the correct disk order, and how parity is rotated across the array.
Question 88: Which of the following is considered the safest method for preserving digital evidence?
- Copy files directly onto a working system
- Save evidence on a network drive with multiple users
- Convert files to a different format for easy access
- Use write-blocking tools (Correct answer)
Correct answer: Use write-blocking tools
Using write-blocking tools is considered the safest method for preserving digital evidence because they physically or logically prevent any modifications from being written to the original storage device. This ensures that the integrity of the evidence is maintained during the acquisition process, preventing accidental or intentional alteration. It is a critical step in forensically sound data collection.
AccessData Certified Examiner (ACE)
The ACE certification validates a digital forensic examiner's proficiency with AccessData's forensic tools including FTK, FTK Imager, Registry Viewer, and Password Recovery Toolkit. It covers evidence acquisition, artifact analysis, network/memory forensics, and legal compliance.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds